Open Source Security Arsenal
Curated intelligence repository of battle-tested open-source security tools, exploits, and pentesting frameworks.
Security Tools
[EXPLOIT] xzbot - PoC Exploit
Unknownxzbot notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
copy-fail-CVE-2026-31431 Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
exploitarium A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
[EXPLOIT] exphub - PoC Exploit
Unknownexphub Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
Penetration_Testing_POC 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
PoC-in-GitHub 📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
[EXPLOIT] cve - PoC Exploit
Unknowncve Gather and update all available and newest CVEs with their PoC.
awesome-hacker-search-engines A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
apple-knowledge A collection of reverse engineered Apple things, as well as a machine-readable database of Apple hardware
getsploit Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.
Findsploit Find exploits in local and online databases instantly
libc-database Build a database of libc offsets to simplify exploitation